Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo HILTON.COM

Group: Clop

Discovered by ransomware.live: 2026-01-25

Estimated attack date: 2026-01-25

Country: US

Description:

[AI generated] Hilton.com is the official online platform for Hilton Worldwide Holdings Inc., a global hospitality company. The site allows users to book rooms in more than 6,100 properties across 119 countries. These properties include luxury resorts, full-service hotels, and extended-stay suites from various Hilton brands such as Hilton Hotels & Resorts, Waldorf Astoria Hotels & Resorts, Conrad Hotels & Resorts, and more.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 213

Compromised Users: 36218

Third Party Employee Credentials: 713


External Attack Surface: 135


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaints@markmonitor.com
  • whoisrequest@markmonitor.com
MX Records
  • hilton-com.mail.protection.outlook.com.
TXT Records
  • pinterest-site-verification=fab28785d21746c26b5e63846c8a1244
  • openai-domain-verification=dv-WXl4EGcBXseW2NSvjnGQ7c4n
  • google-site-verification=xyNJMjK1EcOsSeUk2Eq2zVy6m5j1IOrB0Rhh6I2eHwk
  • aliyun-site-verification=4f44a38c-7524-4da8-8168-b81df754ade3
  • google-site-verification=qPR176c4cQSYmrueNbHi2gV2CHxyMAM9B5p3B7MbJQc
  • google-site-verification=nKb4lBpqoXlAgv5XAJ_GXYff65WEjKWT-dpEo6QZCyk
  • 8T7Av6D/qTIXYt3u6j+Q8R1yHA2fmnvHFTFSs330fbpwD9GVfig+Kbr0nKYcRa6nimKnS8rPj5WQEZAfCLH+vQ==
  • _xp4chx78cccivyyzbgc5acahqp3nneq
  • facebook-domain-verification=puz5qxmn1l3oovw5dyz9krza3f31j6
  • adobe-idp-site-verification=be8fc4ab-a4c7-4beb-93a3-d0794fe41ad8
  • _4v4aops4gbrteu04fox2hwujxwim9en
  • Dynatrace-site-verification=006934ba-06f9-4a24-b0b0-ea536f9103f1__ioig2u5338qlpebr9cam87ormd
  • _mtic2tnhspyudt6lk7f9ympb1cu9hqo
  • v=spf1 include:spf.protection.outlook.com include:_spf-a.hilton.com include:_spf-b.hilton.com include:_spf-c.hilton.com -all
  • _5t8qm7pysb8pi8d0b2xg8sewecbgh4l
  • docker-verification=e41990db-cd57-47de-b7e7-edac7ec64644
  • atlassian-domain-verification=zHCePPwQQy2aLJKC0MEKytJhhy9TWkcbuVks5PXrDtaf8bHa2fdLa75N0CaBstRE
  • google-site-verification=TFgzLWPb5vVPeLn-2F55TvHEQwkOR1jnuMNE4PSh0Jc
  • MS=ms29418927
  • smartsheet-site-validation=RauDwEeqRNL6v1erZN75P1IoP54ZAvlN
  • 7284b5a9499c7e61960d643b6d6a7406af4f825c0f1a244028400579f1ad8264
  • 32wp5fj417ntzpp5c0nkp5j9w347yx5p
  • h1-domain-verification=pEF3wxvPPGThE9Y4zkAkBZMUrZyAu9fjwz2BGaqhWZ9UULoS
  • 00d41000000xoxteao
  • nintex.5e383764d5c41d0e7caeda2c
  • adobe-idp-site-verification=1187c0c2-6b1d-436c-a210-4c61e3d48517
  • uber-domain-verification=a7624827-7aae-4d9b-92e7-2d3fe4b7c5a9
  • sophos-domain-verification=951f84e7ee07b60becedee08eaadc31dba7950440e5d04764473201bb969221e
Cloud / SaaS Services Detected
Adobe Atlassian Microsoft 365 Sophos

Leak Screenshot:

Leak Screenshot